CVE-2024-28072

A highly privileged account can overwrite arbitrary files on the system with log output. The log file path tags were not sanitized properly.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:solarwinds:serv-u:*:*:*:*:*:*:*:*
cpe:2.3:a:solarwinds:serv-u:15.4.2:-:*:*:*:*:*:*

History

25 Feb 2025, 17:12

Type Values Removed Values Added
First Time Solarwinds
Solarwinds serv-u
CPE cpe:2.3:a:solarwinds:serv-u:15.4.2:-:*:*:*:*:*:*
cpe:2.3:a:solarwinds:serv-u:*:*:*:*:*:*:*:*
CWE NVD-CWE-noinfo
References () https://solarwindscore.my.site.com/SuccessCenter/s/article/Serv-U-15-4-2-Hotfix-1-Release-Notes?language=en_US - () https://solarwindscore.my.site.com/SuccessCenter/s/article/Serv-U-15-4-2-Hotfix-1-Release-Notes?language=en_US - Release Notes
References () https://www.solarwinds.com/trust-center/security-advisories/CVE-2024-28072 - () https://www.solarwinds.com/trust-center/security-advisories/CVE-2024-28072 - Vendor Advisory

21 Nov 2024, 09:05

Type Values Removed Values Added
Summary
  • (es) Una cuenta con muchos privilegios puede sobrescribir archivos arbitrarios en el sistema con resultados de registro. Las etiquetas de ruta del archivo de registro no se sanitizaron adecuadamente.
References () https://solarwindscore.my.site.com/SuccessCenter/s/article/Serv-U-15-4-2-Hotfix-1-Release-Notes?language=en_US - () https://solarwindscore.my.site.com/SuccessCenter/s/article/Serv-U-15-4-2-Hotfix-1-Release-Notes?language=en_US -
References () https://www.solarwinds.com/trust-center/security-advisories/CVE-2024-28072 - () https://www.solarwinds.com/trust-center/security-advisories/CVE-2024-28072 -

03 May 2024, 08:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-05-03 08:15

Updated : 2025-02-25 17:12


NVD link : CVE-2024-28072

Mitre link : CVE-2024-28072

CVE.ORG link : CVE-2024-28072


JSON object : View

Products Affected

solarwinds

  • serv-u
CWE
CWE-532

Insertion of Sensitive Information into Log File

NVD-CWE-noinfo